تعديل كود برمجي لا هنتم ضروري Html

هذا كود برمجي لصفحة خانة البحث تقوم بالبحث عن شيء تطلع النتائج في الصفحة نفسها

الذي أريده هو وضع هذه خانة البحث في القائمة الرئيسية ولكن عندما اضغط بحث لا اريد النتائج تظهر في نفس الصفحة

اريدها في صفحة ثانية منعزلة أو في نفس الصفحة ولكن اهم شيء تبعد المساحة الموجودة التي في الصفح , لان خانة البحث هذه عندما اضعها في الصفحة تاخذ المكان كله وتنزل الاقسام تحت لان المساحة التي ياخذها هي مكان نتائج البحث :

تجربة الموقع لرؤية المشكلة : https://flopyeye.com/food.php

الاسم : امجد

كلمة السر:123

الكود:::

<?php

@include 'config.php';

session_start();

$user_id = $_SESSION['user_id'];

if(!isset($user_id)){

  header('location:login.php');

};

if(isset($_POST['add_to_wishlist'])){

  $pid = $_POST['pid'];

  $pid = filter_var($pid, FILTER_SANITIZE_STRING);

  $p_name = $_POST['p_name'];

  $p_name = filter_var($p_name, FILTER_SANITIZE_STRING);

  $p_price = $_POST['p_price'];

  $p_price = filter_var($p_price, FILTER_SANITIZE_STRING);

  $p_image = $_POST['p_image'];

  $p_image = filter_var($p_image, FILTER_SANITIZE_STRING);

  $check_wishlist_numbers = $conn->prepare("SELECT * FROM `wishlist` WHERE name = ? AND user_id = ?");

  $check_wishlist_numbers->execute([$p_name, $user_id]);

  $check_cart_numbers = $conn->prepare("SELECT * FROM `cart` WHERE name = ? AND user_id = ?");

  $check_cart_numbers->execute([$p_name, $user_id]);

  if($check_wishlist_numbers->rowCount() > 0){

   $message[] = 'already added to wishlist!';

  }elseif($check_cart_numbers->rowCount() > 0){

   $message[] = 'already added to cart!';

  }else{

   $insert_wishlist = $conn->prepare("INSERT INTO `wishlist`(user_id, pid, name, price, image) VALUES(?,?,?,?,?)");

   $insert_wishlist->execute([$user_id, $pid, $p_name, $p_price, $p_image]);

   $message[] = 'added to wishlist!';

  }

}

if(isset($_POST['add_to_cart'])){

  $pid = $_POST['pid'];

  $pid = filter_var($pid, FILTER_SANITIZE_STRING);

  $p_name = $_POST['p_name'];

  $p_name = filter_var($p_name, FILTER_SANITIZE_STRING);

  $p_price = $_POST['p_price'];

  $p_price = filter_var($p_price, FILTER_SANITIZE_STRING);

  $p_image = $_POST['p_image'];

  $p_image = filter_var($p_image, FILTER_SANITIZE_STRING);

  $p_qty = $_POST['p_qty'];

  $p_qty = filter_var($p_qty, FILTER_SANITIZE_STRING);

  $check_cart_numbers = $conn->prepare("SELECT * FROM `cart` WHERE name = ? AND user_id = ?");

  $check_cart_numbers->execute([$p_name, $user_id]);

  if($check_cart_numbers->rowCount() > 0){

   $message[] = 'already added to cart!';

  }else{

   $check_wishlist_numbers = $conn->prepare("SELECT * FROM `wishlist` WHERE name = ? AND user_id = ?");

   $check_wishlist_numbers->execute([$p_name, $user_id]);

   if($check_wishlist_numbers->rowCount() > 0){

     $delete_wishlist = $conn->prepare("DELETE FROM `wishlist` WHERE name = ? AND user_id = ?");

     $delete_wishlist->execute([$p_name, $user_id]);

   }

   $insert_cart = $conn->prepare("INSERT INTO `cart`(user_id, pid, name, price, quantity, image) VALUES(?,?,?,?,?,?)");

   $insert_cart->execute([$user_id, $pid, $p_name, $p_price, $p_qty, $p_image]);

   $message[] = 'added to cart!';

  }

}

?>

<!DOCTYPE html>

<html lang="en">

<head>

  <meta charset="UTF-8">

  <meta http-equiv="X-UA-Compatible" content="IE=edge">

  <meta name="viewport" content="width=device-width, initial-scale=1.0">

  <title>search page</title>

  <!-- font awesome cdn link -->

  <link rel="stylesheet" href="https://cdnjs.cloudflare.co...">

  <!-- custom css file link -->

  <link rel="stylesheet" href="css/style.css">

</head>

<body>

<section class="search-form"dir="rtl">

  <form action="" method="POST">

   <input type="text" class="box" name="search_box" placeholder="إبحث عن طلبك">

   <input type="submit" name="search_btn" value="بحث" class="btn">

  </form>

</section>

<?php

?>

<section class="products" style="padding-top: 0; min-height:100vh;">

  <div class="box-container">

  <?php

   if(isset($_POST['search_btn'])){

   $search_box = $_POST['search_box'];

   $search_box = filter_var($search_box, FILTER_SANITIZE_STRING);

   $select_products = $conn->prepare("SELECT * FROM `products` WHERE name LIKE '%{$search_box}%' OR category LIKE '%{$search_box}%'");

   $select_products->execute();

   if($select_products->rowCount() > 0){

     while($fetch_products = $select_products->fetch(PDO::FETCH_ASSOC)){ 

  ?>

  <form action="" class="box" method="POST">

   <div class="price">$<span><?= $fetch_products['price']; ?></span>/-</div>

   <a href="view_page.php?pid=<?= $fetch_products['id']; ?>" class="fas fa-eye"></a>

   <img src="uploaded_img/<?= $fetch_products['image']; ?>" alt="">

   <div class="name"><?= $fetch_products['name']; ?></div>

   <input type="hidden" name="pid" value="<?= $fetch_products['id']; ?>">

   <input type="hidden" name="p_name" value="<?= $fetch_products['name']; ?>">

   <input type="hidden" name="p_price" value="<?= $fetch_products['price']; ?>">

   <input type="hidden" name="p_image" value="<?= $fetch_products['image']; ?>">

   <input type="number" min="1" value="1" name="p_qty" class="qty">

   <input type="submit" value="add to wishlist" class="option-btn" name="add_to_wishlist">

   <input type="submit" value="add to cart" class="btn" name="add_to_cart">

  </form>

  <?php

     }

   }else{

     echo '<p class="empty">no result found!</p>';

   }

  };

  ?>

  </div>

</section>

<script src="js/script.js"></script>

</body>

</html>


الأفضل إنشاء صفحة بحث منفصلة، أي في القائمة الرئيسية header.php أو index.php اكتب التالي لإرسال الطلب إلى ملف search.php

<section class="search-form" dir="rtl">
  <form action="search.php" method="GET">
    <input type="text" class="box" name="search_box" placeholder="إبحث عن طلبك" required>
    <input type="submit" value="بحث" class="btn">
  </form>
</section>

وأنشئ صفحة جديدة باسم search.php

<?php
@include 'config.php';
session_start();


$user_id = $_SESSION['user_id'];


if(!isset($user_id)){
  header('location:login.php');
}


if(isset($_POST['add_to_wishlist'])){
  $pid = $_POST['pid'];
  $pid = filter_var($pid, FILTER_SANITIZE_STRING);
  $p_name = $_POST['p_name'];
  $p_name = filter_var($p_name, FILTER_SANITIZE_STRING);
  $p_price = $_POST['p_price'];
  $p_price = filter_var($p_price, FILTER_SANITIZE_STRING);
  $p_image = $_POST['p_image'];
  $p_image = filter_var($p_image, FILTER_SANITIZE_STRING);


  $check_wishlist_numbers = $conn->prepare("SELECT * FROM `wishlist` WHERE name = ? AND user_id = ?");
  $check_wishlist_numbers->execute([$p_name, $user_id]);


  $check_cart_numbers = $conn->prepare("SELECT * FROM `cart` WHERE name = ? AND user_id = ?");
  $check_cart_numbers->execute([$p_name, $user_id]);


  if($check_wishlist_numbers->rowCount() > 0){
    $message[] = 'already added to wishlist!';
  }elseif($check_cart_numbers->rowCount() > 0){
    $message[] = 'already added to cart!';
  }else{
    $insert_wishlist = $conn->prepare("INSERT INTO `wishlist`(user_id, pid, name, price, image) VALUES(?,?,?,?,?)");
    $insert_wishlist->execute([$user_id, $pid, $p_name, $p_price, $p_image]);
    $message[] = 'added to wishlist!';
  }
}


if(isset($_POST['add_to_cart'])){
  $pid = $_POST['pid'];
  $pid = filter_var($pid, FILTER_SANITIZE_STRING);
  $p_name = $_POST['p_name'];
  $p_name = filter_var($p_name, FILTER_SANITIZE_STRING);
  $p_price = $_POST['p_price'];
  $p_price = filter_var($p_price, FILTER_SANITIZE_STRING);
  $p_image = $_POST['p_image'];
  $p_image = filter_var($p_image, FILTER_SANITIZE_STRING);
  $p_qty = $_POST['p_qty'];
  $p_qty = filter_var($p_qty, FILTER_SANITIZE_STRING);


  $check_cart_numbers = $conn->prepare("SELECT * FROM `cart` WHERE name = ? AND user_id = ?");
  $check_cart_numbers->execute([$p_name, $user_id]);


  if($check_cart_numbers->rowCount() > 0){
    $message[] = 'already added to cart!';
  }else{
    $check_wishlist_numbers = $conn->prepare("SELECT * FROM `wishlist` WHERE name = ? AND user_id = ?");
    $check_wishlist_numbers->execute([$p_name, $user_id]);


    if($check_wishlist_numbers->rowCount() > 0){
      $delete_wishlist = $conn->prepare("DELETE FROM `wishlist` WHERE name = ? AND user_id = ?");
      $delete_wishlist->execute([$p_name, $user_id]);
    }


    $insert_cart = $conn->prepare("INSERT INTO `cart`(user_id, pid, name, price, quantity, image) VALUES(?,?,?,?,?,?)");
    $insert_cart->execute([$user_id, $pid, $p_name, $p_price, $p_qty, $p_image]);
    $message[] = 'added to cart!';
  }
}
?>


<!DOCTYPE html>
<html lang="ar">
<head>
  <meta charset="UTF-8">
  <meta http-equiv="X-UA-Compatible" content="IE=edge">
  <meta name="viewport" content="width=device-width, initial-scale=1.0">
  <title>نتائج البحث</title>
  <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.1.1/css/all.min.css">
  <link rel="stylesheet" href="css/style.css">
</head>
<body>


<?php include 'header.php'; ?>


<section class="search-form" dir="rtl">
  <form action="" method="GET">
    <input type="text" class="box" name="search_box" placeholder="إبحث عن طلبك" value="<?= isset($_GET['search_box']) ? htmlspecialchars($_GET['search_box']) : ''; ?>">
    <input type="submit" value="بحث" class="btn">
  </form>
</section>


<section class="products" style="padding-top: 2rem; min-height:100vh;" dir="rtl">
  <div class="box-container">
  <?php
    if(isset($_GET['search_box']) && !empty($_GET['search_box'])){
      $search_box = $_GET['search_box'];
      $search_box = filter_var($search_box, FILTER_SANITIZE_STRING);
      
      $select_products = $conn->prepare("SELECT * FROM `products` WHERE name LIKE ? OR category LIKE ?");
      $select_products->execute(["%{$search_box}%", "%{$search_box}%"]);


      if($select_products->rowCount() > 0){
        echo '<h1 class="title">نتائج البحث عن: "' . htmlspecialchars($search_box) . '"</h1>';
        
        while($fetch_products = $select_products->fetch(PDO::FETCH_ASSOC)){ 
  ?>
    <form action="" class="box" method="POST">
      <div class="price">$<span><?= $fetch_products['price']; ?></span>/-</div>
      <a href="view_page.php?pid=<?= $fetch_products['id']; ?>" class="fas fa-eye"></a>
      <img src="uploaded_img/<?= $fetch_products['image']; ?>" alt="">
      <div class="name"><?= $fetch_products['name']; ?></div>
      <input type="hidden" name="pid" value="<?= $fetch_products['id']; ?>">
      <input type="hidden" name="p_name" value="<?= $fetch_products['name']; ?>">
      <input type="hidden" name="p_price" value="<?= $fetch_products['price']; ?>">
      <input type="hidden" name="p_image" value="<?= $fetch_products['image']; ?>">
      <input type="number" min="1" value="1" name="p_qty" class="qty">
      <input type="submit" value="إضافة للمفضلة" class="option-btn" name="add_to_wishlist">
      <input type="submit" value="إضافة للسلة" class="btn" name="add_to_cart">
    </form>
  <?php
        }
      }else{
        echo '<p class="empty">لا توجد نتائج للبحث عن: "' . htmlspecialchars($search_box) . '"</p>';
      }
    }else{
      echo '<p class="empty">الرجاء إدخال كلمة للبحث</p>';
    }
  ?>
  </div>
</section>


<?php include 'footer.php'; ?>


<script src="js/script.js"></script>
</body>
</html>

ولاحظ أنني قمت بتغيير الطلب من POST إلى GET للبحث حيث ذلك أفضل لمحركات البحث من أجل رؤية ما يتم البحث عنه حيث سيظهر الرابط كالتالي:

https://test.com/search.php?search_box=laptop
بدلاً من
https://test.com/search.php 

واستخدمت prepared statements للحماية من هجمات SQL Injection، وكذلك أضفت htmlspecialchars() للحماية من هجمات XSS.